3 ms·
This means that DHCP clients that use bash and have DHCP server-controlled environment variables can have commands injected (as root) by a malicious DHCP server
by jeffmcjunkin 12y ago
This means that DHCP clients that use bash and have DHCP server-controlled environment variables can have commands injected (as root) by a malicious DHCP server.
Notably, attackers in an unhardened network can reply to DHCP clients themselves, even if there's already a DHCP server on the network. So it's not just the sysadmin who can exploit this, but anyone on the same network (broadcast domain) as the vulnerable DHCP client.
- akkartik 12y agoAlright, I'm shutting down my cable modem. See y'all later.
- krek 12y agoThis is best plain English explanation I've seen yet (been looking for an hour). Thanks.
- nqzero 12y agowhy is a DHCP client calling bash for anything ? that's just a terrible way to program. and doubly so for passing unscrubbed data to it as environment variables